Oh wait you can't. Which is why we had to turn to our government intelligence services to provide assistance.
So stop pretending like companies can defend against state sponsors who are buying 0-days for $100k+ like it's candy.
https://lobste.rs/s/o6x9b3/tech_s_masturbatory_historiograph...
I described what I learned about how high-assurance security builds stuff here:
As I often said, compare anything from security market advertised as secure against stuff on that list. If they're missing something, they're probably insecure. Now, I'm still not saying you can stop nation states and all 0-days. I am saying that most of the $100k 0-days are preventable with architectures like above with apps in safe languages with guards separating trusted things from untrusted things. Ada has also been around a long time with Rust getting popular now.
What makes most companies not use stuff like that isn't that level of security being unachievable: they just don't want to for management's reasons which range from arbitrary to sound practices in a profit-focused environment.
"I don't believe you." You can't just change the organization, culture, and procedures of a company just by throwing money at consultants.
That's like saying a big family can solve their feuds and mental illnesses just by writing a check to team of group therapists and lawyers.
Security is hard. So hard that no matter what amount of money you spend you will still be vulnerable, but maybe a bit less so. There are no absolutes in this.